Summary
Konfir protects your data at every step of the verification process. Every connection is encrypted, every access is read-only and time-limited, and your login credentials are never seen or stored.
Connection Security
When you connect a source (Banking, HMRC, or Payroll), the connection is made using secure, encrypted APIs:
You log in directly with the data provider using their secure authentication
Konfir receives only a defined, limited set of data
Access is one-time and read-only
Access is automatically revoked once your data is retrieved
Why this matters: Unlike traditional referencing, no data is ever sent by email, spreadsheets, or PDFs between HR teams. Everything is handled through secure, encrypted channels with audit trails.
Platform Security
Konfir protects your data through multiple reinforcing layers:
Encryption: All data is encrypted both in transit and at rest using industry-standard protocols
Role-based access controls: Only authorised personnel can access sensitive systems, with permissions tailored to their role
Monitoring & audit logging: Continuous monitoring detects anomalous behaviour
Operational security testing: Regular vulnerability management and independent testing
Secure cloud infrastructure: Hosted on AWS, designed for resilient and secure operation
Independent certification
Konfir's security practices are independently verified:
ISO 27001 - International standard for information security management
UK Digital Identity & Attributes Trust Framework (DIATF) - Registered
UK GDPR & Data Protection Act 2018 - Fully compliant
